Audit Risk Models: Inherent, Control, and Detection Risk
Master the audit risk model and its three components, including inherent risk, control risk, and detection risk, as they apply to IS auditing for the CISA exam.
The Audit Risk Model
The audit risk model is a fundamental framework that guides auditors in planning and executing audit engagements. Audit risk is the probability that an auditor issues an inappropriate opinion on the subject matter being audited. Understanding this model is essential for CISA candidates, as it directly influences audit scope, resource allocation, and testing strategies.
The Audit Risk Formula
Audit Risk equals Inherent Risk multiplied by Control Risk multiplied by Detection Risk. This multiplicative relationship means that auditors can manage overall audit risk by adjusting any of the three components, though detection risk is the only component directly within the auditor's control.
Components of Audit Risk
Inherent Risk
Inherent risk represents the susceptibility of an area to material misstatement or error, assuming no internal controls exist. Factors that increase inherent risk include:
- Complexity of systems or transactions that create more opportunities for errors
- Volume of transactions processed through the system
- Degree of manual intervention required in automated processes
- Sensitivity of data that increases the motivation for unauthorized access
- Recent system changes that may introduce new vulnerabilities
Control Risk
Control risk is the probability that internal controls will fail to prevent or detect material misstatements or errors. A well-designed and effectively operating control environment reduces control risk. Auditors assess control risk by evaluating the design adequacy and operating effectiveness of relevant controls through testing.
Detection Risk
Detection risk is the probability that audit procedures will fail to identify existing misstatements or errors. This is the only component the auditor directly controls. When inherent risk and control risk are high, auditors must reduce detection risk by performing more extensive and rigorous testing procedures.
Applying the Model in IS Auditing
In IS auditing, the risk model helps determine where to focus audit resources. Systems with high inherent risk, such as those processing financial transactions or handling sensitive data, require more attention. If controls over these systems are assessed as weak, the auditor must compensate by increasing the nature, timing, and extent of substantive testing.
Practical Application
Consider an organization's payroll system. Inherent risk may be high due to the volume and sensitivity of transactions. If the auditor tests controls and finds weaknesses in access management and change control, control risk is assessed as high. To maintain acceptable audit risk, the auditor must reduce detection risk by expanding sample sizes, using more sophisticated analytical procedures, and performing additional verification steps.
Key Exam Points
Remember that inherent risk and control risk exist independently of the audit. The auditor assesses these risks but cannot change them. Detection risk is managed through audit planning and execution. Higher assessed inherent and control risks require lower detection risk, meaning more extensive audit procedures.